Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22407

Опубликовано: 16 янв. 2024
Источник: nvd
CVSS3: 4.9
CVSS3: 6.5
EPSS Низкий

Описание

Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementation, users lacking 'write' permissions for orders are still able to change the order state. This issue has been addressed and users are advised to update to Shopware 6.5.7.4. For older versions of 6.1, 6.2, 6.3 and 6.4 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*
Версия до 6.5.7.4 (исключая)

EPSS

Процентиль: 29%
0.00108
Низкий

4.9 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.9
github
около 2 лет назад

Broken Access Control order API in Shopware

EPSS

Процентиль: 29%
0.00108
Низкий

4.9 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-284